Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

True - it's the (many many documented[1]) cases where the SQLi grabs the password_cleartext column, not the encrypted_hash one that worry me here.

[1] http://plaintextoffenders.com/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: